Cyber Security and Leadership Solutions

Total Page:16

File Type:pdf, Size:1020Kb

Cyber Security and Leadership Solutions Cyber Security and Leadership Solutions James Risler Manager – Security Content Development MBA, CISSP #456200, CCIE# 15412 [email protected] © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 1 • The “Why” • Trends • Threat Landscape • Examples of Cyber Attacks • Business Challenge • People Problem • Recommendations • Conclusion & Q&A © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 2 The “Why” Anthem Home Depot JP Morgan Adobe Target Univ. of MD Neiman Marcus TJ Maxx Sony Zappos LinkedIn Citigroup Florida Courts http://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/ © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 3 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 4 Attacks per vertical segment • Over 15% of attacks are targeted at financial institutions • Attacks include : DDoS Spyware Ransomware Mobile devices SPAM Web Exploits • Source : IDC ™ © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 5 • 2008 – 100 Million Credit and debit card numbers stolen by spyware from Heartland Payment Systems • 2014 – 76 Million household accounts and 7 million SMB accounts compromised at JP Morgan Chase • 2015 - DDoS attack launched on OP-Pohjola and Danske Bank • ... And more : European Central Bank extortion attempt Multi-bank attack by Eurograbber © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 6 Threat Landscape is Evolving… Reputation Enterpris Antivirus IDS/IPS Intelligence (Global) e (Host- (Network and and Response Based) Perimeter) Analytics Sandboxing (Cloud) Spyware Increased APT’S Attack and Cyberwar Worms Rootkits Surface 2000 2005 2010 Tomorrow © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 7 Missed by Point-in-time 100 percent of companies surveyedDetection by Cisco have connections to domains that are known to host malicious files or services. (2014 CASR) It is a Community that hides in plain sight © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 8 Cisco Social Engineering Technical Exploit Zero-day Attack Phishing, Spam Patching, new Unknown code Malvertising vulnerabilities exploits © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 9 Top Cyber Risks for Users Untrustworthy sources Clickfraud and Adware 10%vs 64% IE requests Chrome requests Outdated browsers running latest running latest version version 2015 Cisco Annual Security Report Sophisticated Attacks, Complex Landscape Hacking Becomes an Industry Phishing, Low Sophistication Botnets ILOVEYOU Nimda Tedroo Aurora Melissa SQL Slammer Rustock Shady Rat Anna Kournikova Conficker Conficker v2 Duqu 1990 1995 2000 2005 2010 2015 2020 Viruses Worms Spyware and Rootkits APTs Cyberware 1990–2000 2000–2005 2005–Today Today + © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 11 How Industrial Hackers Monetize the Opportunity Exploits Mobile Malware $100k-$300K $150 Spam Credit $50/500K emails Social Card Data Security $0.25−$60 $1 Medical Global Record Cybercrime >$50 Market: DDoS $ $450B-$1T Facebook Account Malware $1 for an account Bank Account Info Development with 15 friends DDoS >$1000 $2500 as a Service depending on account (commercial malware) ~$7/hour type and balance Welcome to the Hackers’ Economy Source: CNBC Impact of a Breach Breach occurs data in of breaches remain Information of up to breaches is stolen in undiscovered for individuals on the black market over last three START HOURS MONTHS YEARS Source: Verizon Data Breach Report 2014 Examples of Cyber Attacks • 4 Key South Korean Targets Phishing against Hyundai Merchant Marine • Infecting Systems Trojan Dropper – DLL library against Windows 7 • Install Spying Modules Key Stroke Logger, Directory Listing, Remote Control & Execution, Remote Control Access • Disable Firewall • Communication Command and control Bot done through a Bulgarian web-based free email server • Regular Reporting and RC4 Encryption and Exporting of Data © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 15 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 16 1. Phish HVAC Vendor Steal credentials – Target hosted web server 2. Scan Network – Determine HVAC vendor access shared web server 1. Upload PHP Script to Web Server – Vulnerability in Application 1. Control of Webserver – Scan for relevant targets for propagation (MSSQLSvc/Billing) 1. Attack Microsoft AD Domain – Steal access tokens on Webserver (Pass-the-hash) © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 17 6. Create new Admin Account in MS AD Domain 7. Propagate to relevant computers (“Angry IP Scanner”) by pass security solutions (Tunneling with PsExec’s) 7. Attack SQL Server – Steal 70 Million PII records (no credit cards because PCI compliant) • Osql.exe • Isql.exe • Bcp.exe © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 18 9. Download POS Malware and install on POS (“Kaptoxa” Malware) 10.Send stolen Credit Card info to network share (FTP transfer) 10.Upload Credit Card information to FTP site © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 19 If you knew you were going to be compromised, would you do security differently? © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 20 Sophisticated Complicit Attackers Users Dynamic Boardroom Threats Engagement Defenders Complex Misaligned Geopolitics Policies © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 21 Industrialization Evolving Borders Compliance of Hackers • Zeus, Phishing, Mules • Traditional Signature • Rapid Growth of Regulatory Enforcement less Effective Requirements: PCI, HIPAA, • Targeted Attacks for Profit Influx of Mobile Devices, BYOD NERC CIP, FISMA, SOX, ISO • Advanced Persistent • Dual Profiles—Personal and • Legal Liabilities Drive Internal Threats (APT) Corporate Requirements • Cyber and Economic • Access Policy Inconsistent, • Little to No Guidance On How Espionage Difficult to Maintain to Meet New Standards © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 22 Cyber Security is a Boardroom Discussion Security Breaches are Costly Security is the #1 Issue for Your Customers Protect Now the Value You Intend to Create Tomorrow 23 © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 23 Summary Cisco 2015 Annual Security Report Key Findings • Lack of Security Leadership in Small companies (only 22 percent respondents see security has high priority) • Gap between CISO and SecOp Manager in terms of confidence • Less than 50% of respondents use following tools: • Identity Administrator or user provisioning • Patching and configuration • Penetration testing or Endpoint Forensics • Vulnerability scanning • Only 40% of companies do Correlated event/log analysis Solution • New approaches to Security through alignment with People, Process and Technology © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 24 • “Caught in the middle are the users. But now, it appears they not only are the targets, but also the complicit enablers of attacks.” • “Users’ careless behavior when using the Internet, combined with targeted campaigns by adversaries, places many industry verticals at higher risk of web malware exposure” • People are part corporate system Solution • Training Programs • Leadership from Executives on down © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 25 New Focus - Attack Continuum BEFORE DURING AFTER Discover Detect Scope Enforce Block Contain Harden Defend Remediate Monitoring Identification Impact Mitigation Visibility and Context Mission Critical Business Systems and Solutions Policies, Process Response Policy Communication and People and Strategy © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 26 • Develop a Cybersecurity Management Framework • 3 Distinct Layers with seven discret focus area 1. Strategy – Define, document, and publish 2. Operational – develop operational standards, process, and proceedures 3. Tactical – implement security controls and monitoring with defined metrics • Critical – Executive Sponsorship • Plane for … Before During and After the Attack What is the critical components of the business? Have you done a risk assessment? Use existing business cases (Target, Home Depot, etc) How will the board respond to a Cyber attack? © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 27 • Threat Landscape Rapidly Changing • Business Leaders must drive security • Business Challenge - Tools, Process, and People • Cybersecurity Framework is critical © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 28 Cisco 2015 Annual Security Report Now available: cisco.com/go/asr2015 Verizon 2015 Data Breach Investigation Report http://www.verizonenterprise.com/DBIR/ © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 29 Questions/Discussion? Thank You http://www.cisco.com/c/dam/en/us/products/collateral/security/cyber security-management-programs.pdf http://www.datacenterdynamics.com/security/ciscos-2015-security- report-its-a-people-problem/94536.fullarticle © 2010 Cisco and/or its affiliates. All rights reserved. Cisco Confidential 31.
Recommended publications
  • The Downadup Codex a Comprehensive Guide to the Threat’S Mechanics
    Security Response The Downadup Codex A comprehensive guide to the threat’s mechanics. Edition 2.0 Introduction Contents Introduction.............................................................1 Since its appearance in late-2008, the Downadup worm has become Editor’s Note............................................................5 one of the most wide-spread threats to hit the Internet for a number of Increase in exploit attempts against MS08-067.....6 years. A complex piece of malicious code, this threat was able to jump W32.Downadup infection statistics.........................8 certain network hurdles, hide in the shadows of network traffic, and New variants of W32.Downadup.B find new ways to propagate.........................................10 defend itself against attack with a deftness not often seen in today’s W32.Downadup and W32.Downadup.B threat landscape. Yet it contained few previously unseen features. What statistics................................................................12 set it apart was the sheer number of tricks it held up its sleeve. Peer-to-peer payload distribution...........................15 Geo-location, fingerprinting, and piracy...............17 It all started in late-October of 2008, we began to receive reports of A lock with no key..................................................19 Small improvements yield big returns..................21 targeted attacks taking advantage of an as-yet unknown vulnerability Attempts at smart network scanning...................23 in Window’s remote procedure call (RPC) service. Microsoft quickly Playing with Universal Plug and Play...................24 released an out-of-band security patch (MS08-067), going so far as to Locking itself out.................................................27 classify the update as “critical” for some operating systems—the high- A new Downadup variant?......................................29 Advanced crypto protection.................................30 est designation for a Microsoft Security Bulletin.
    [Show full text]
  • Post-Mortem of a Zombie: Conficker Cleanup After Six Years Hadi Asghari, Michael Ciere, and Michel J.G
    Post-Mortem of a Zombie: Conficker Cleanup After Six Years Hadi Asghari, Michael Ciere, and Michel J.G. van Eeten, Delft University of Technology https://www.usenix.org/conference/usenixsecurity15/technical-sessions/presentation/asghari This paper is included in the Proceedings of the 24th USENIX Security Symposium August 12–14, 2015 • Washington, D.C. ISBN 978-1-939133-11-3 Open access to the Proceedings of the 24th USENIX Security Symposium is sponsored by USENIX Post-Mortem of a Zombie: Conficker Cleanup After Six Years Hadi Asghari, Michael Ciere and Michel J.G. van Eeten Delft University of Technology Abstract more sophisticated C&C mechanisms that are increas- ingly resilient against takeover attempts [30]. Research on botnet mitigation has focused predomi- In pale contrast to this wealth of work stands the lim- nantly on methods to technically disrupt the command- ited research into the other side of botnet mitigation: and-control infrastructure. Much less is known about the cleanup of the infected machines of end users. Af- effectiveness of large-scale efforts to clean up infected ter a botnet is successfully sinkholed, the bots or zom- machines. We analyze longitudinal data from the sink- bies basically remain waiting for the attackers to find hole of Conficker, one the largest botnets ever seen, to as- a way to reconnect to them, update their binaries and sess the impact of what has been emerging as a best prac- move the machines out of the sinkhole. This happens tice: national anti-botnet initiatives that support large- with some regularity. The recent sinkholing attempt of scale cleanup of end user machines.
    [Show full text]
  • Undergraduate Report
    UNDERGRADUATE REPORT Attack Evolution: Identifying Attack Evolution Characteristics to Predict Future Attacks by MaryTheresa Monahan-Pendergast Advisor: UG 2006-6 IINSTITUTE FOR SYSTEMSR RESEARCH ISR develops, applies and teaches advanced methodologies of design and analysis to solve complex, hierarchical, heterogeneous and dynamic problems of engineering technology and systems for industry and government. ISR is a permanent institute of the University of Maryland, within the Glenn L. Martin Institute of Technol- ogy/A. James Clark School of Engineering. It is a National Science Foundation Engineering Research Center. Web site http://www.isr.umd.edu Attack Evolution 1 Attack Evolution: Identifying Attack Evolution Characteristics To Predict Future Attacks MaryTheresa Monahan-Pendergast Dr. Michel Cukier Dr. Linda C. Schmidt Dr. Paige Smith Institute of Systems Research University of Maryland Attack Evolution 2 ABSTRACT Several approaches can be considered to predict the evolution of computer security attacks, such as statistical approaches and “Red Teams.” This research proposes a third and completely novel approach for predicting the evolution of an attack threat. Our goal is to move from the destructive nature and malicious intent associated with an attack to the root of what an attack creation is: having successfully solved a complex problem. By approaching attacks from the perspective of the creator, we will chart the way in which attacks are developed over time and attempt to extract evolutionary patterns. These patterns will eventually
    [Show full text]
  • The Botnet Chronicles a Journey to Infamy
    The Botnet Chronicles A Journey to Infamy Trend Micro, Incorporated Rik Ferguson Senior Security Advisor A Trend Micro White Paper I November 2010 The Botnet Chronicles A Journey to Infamy CONTENTS A Prelude to Evolution ....................................................................................................................4 The Botnet Saga Begins .................................................................................................................5 The Birth of Organized Crime .........................................................................................................7 The Security War Rages On ........................................................................................................... 8 Lost in the White Noise................................................................................................................. 10 Where Do We Go from Here? .......................................................................................................... 11 References ...................................................................................................................................... 12 2 WHITE PAPER I THE BOTNET CHRONICLES: A JOURNEY TO INFAMY The Botnet Chronicles A Journey to Infamy The botnet time line below shows a rundown of the botnets discussed in this white paper. Clicking each botnet’s name in blue will bring you to the page where it is described in more detail. To go back to the time line below from each page, click the ~ at the end of the section. 3 WHITE
    [Show full text]
  • Computer Security CS 426 Lecture 15
    Computer Security CS 426 Lecture 15 Malwares CS426 Fall 2010/Lecture 15 1 Trapdoor • SttitittSecret entry point into a system – Specific user identifier or password that circumvents normal security procedures. • Commonlyyy used by developers – Could be included in a compiler. CS426 Fall 2010/Lecture 15 2 Logic Bomb • Embedded in legitimate programs • Activated when specified conditions met – E.g., presence/absence of some file; Particular date/time or particular user • When triggered, typically damages system – Modify/delete files/disks CS426 Fall 2010/Lecture 15 3 Examppgle of Logic Bomb • In 1982 , the Trans-Siber ian Pipe line inc iden t occurred. A KGB operative was to steal the plans fhititdtltditfor a sophisticated control system and its software from a Canadian firm, for use on their Siberi an pi peli ne. The CIA was tippe d o ff by documents in the Farewell Dossier and had the company itlibbithinsert a logic bomb in the program for sabotage purposes. This eventually resulted in "the most monu mental non-nu clear ex plosion and fire ever seen from space“. CS426 Fall 2010/Lecture 15 4 Trojan Horse • Program with an overt Example: Attacker: (expected) and covert effect Place the following file cp /bin/sh /tmp/.xxsh – Appears normal/expected chmod u+s,o+x /tmp/.xxsh – Covert effect violates security policy rm ./ls • User tricked into executing ls $* Trojan horse as /homes/victim/ls – Expects (and sees) overt behavior – Covert effect performed with • Victim user’s authorization ls CS426 Fall 2010/Lecture 15 5 Virus • Self-replicating
    [Show full text]
  • Wannacry Ransomware
    KNOW THE UNKNOWN® Success Story: WannaCry Ransomware WHITE PAPER Challenge Stopping a Worm & Saving Millions Worms like WannaCry and Petya operate as essentially Even the most recent of these attacks like WannaCry and zero-day attacks: they can lie dormant on our networks Petya still echo the basic principles of past-worms, and as and then rapidly spread between devices upon waking up. such, they are both preventable and stoppable. During The consequences of being hit by one is dramatic: precious the Code Red, Nimda, and ILOVEYOU attacks of the early- data is either ransom-locked or wiped and thus often 2000s, businesses that had invested in a NIKSUN-like irrecoverable. This means millions in lost data, restoration solution were able to run a rapid report to get a list of fees, public relations, and stock-holder confidence. all infected devices and cut them off from their network. Instead of thousands of machines being affected, they When FedEx was hit by Petya, for example, their subsidiary were able to resolve the incident with minor losses of TNT Express experienced “widespread service delays” and hundreds or less. This process takes a mere few minutes were unable to “fully restore all of the affected systems and thus could have saved Reckitt Benckiser from their and recover all of the critical business data that was hour-long attack. encrypted by the virus.”1 Shares in the company dropped 3.4% in the wake of the attack.2 Total, 100% visibility is simply the only way to stop these worms from becoming too damaging.
    [Show full text]
  • Iptrust Botnet / Malware Dictionary This List Shows the Most Common Botnet and Malware Variants Tracked by Iptrust
    ipTrust Botnet / Malware Dictionary This list shows the most common botnet and malware variants tracked by ipTrust. This is not intended to be an exhaustive list, since new threat intelligence is always being added into our global Reputation Engine. NAME DESCRIPTION Conficker A/B Conficker A/B is a downloader worm that is used to propagate additional malware. The original malware it was after was rogue AV - but the army's current focus is undefined. At this point it has no other purpose but to spread. Propagation methods include a Microsoft server service vulnerability (MS08-067) - weakly protected network shares - and removable devices like USB keys. Once on a machine, it will attach itself to current processes such as explorer.exe and search for other vulnerable machines across the network. Using a list of passwords and actively searching for legitimate usernames - the ... Mariposa Mariposa was first observed in May 2009 as an emerging botnet. Since then it has infected an ever- growing number of systems; currently, in the millions. Mariposa works by installing itself in a hidden location on the compromised system and injecting code into the critical process ͞ĞdžƉůŽƌĞƌ͘ĞdžĞ͘͟/ƚŝƐknown to affect all modern Windows versions, editing the registry to allow it to automatically start upon login. Additionally, there is a guard that prevents deletion while running, and it automatically restarts upon crash/restart of explorer.exe. In essence, Mariposa opens a backdoor on the compromised computer, which grants full shell access to ... Unknown A botnet is designated 'unknown' when it is first being tracked, or before it is given a publicly- known common name.
    [Show full text]
  • Nimda Worm Shows You Can't Always Patch Fast Enough
    Research Publication Date: 19 September 2001 ID Number: FT-14-5524 Nimda Worm Shows You Can't Always Patch Fast Enough John Pescatore Nimda bundles several known exploits against Internet Information Server and other Microsoft software. Enterprises with Web applications should start to investigate less- vulnerable Web server products. © 2001 Gartner, Inc. and/or its Affiliates. All Rights Reserved. Reproduction of this publication in any form without prior written permission is forbidden. The information contained herein has been obtained from sources believed to be reliable. Gartner disclaims all warranties as to the accuracy, completeness or adequacy of such information. Gartner shall have no liability for errors, omissions or inadequacies in the information contained herein or for interpretations thereof. The reader assumes sole responsibility for the selection of these materials to achieve its intended results. The opinions expressed herein are subject to change without notice. NEWS ANALYSIS Event On 18 September 2001, a new mass-mailing computer worm began infecting computers worldwide, damaging local files as well as remote network files. The w32.Nimda.A @ mm worm can spread through e-mail, file sharing and Web site downloads. For more information, visit: http://www.microsoft.com/technet/security/topics/Nimda.asp or http://www.sarc.com/avcenter/venc/data/[email protected]. Analysis As a "rollup worm," Nimda bundles several known exploits against Microsoft's Internet Information Server (IIS), Internet Explorer (IE) browser, and operating systems such as Windows 2000 and Windows XP, which have IIS and IE embedded in their code. To protect against Nimda, Microsoft recommends installing numerous patches and service packs on virtually every PC and server running IE, IIS Web servers or the Outlook Express e-mail client.
    [Show full text]
  • Download Slides
    Scott Wu Point in time cleaning vs. RTP MSRT vs. Microsoft Security Essentials Threat events & impacts More on MSRT / Security Essentials MSRT Microsoft Windows Malicious Software Removal Tool Deployed to Windows Update, etc. monthly since 2005 On-demand scan on prevalent malware Microsoft Security Essentials Full AV RTP Inception in Oct 2009 RTP is the solution One-off cleaner has its role Quiikck response Workaround Baseline ecosystem cleaning Industrypy response & collaboration Threat Events Worms (some are bots) have longer lifespans Rogues move on quicker MarMar 2010 2010 Apr Apr 2010 2010 May May 2010 2010 Jun Jun 2010 2010 Jul Jul 2010 2010 Aug Aug 2010 2010 1,237,15 FrethogFrethog 979,427 979,427 Frethog Frethog 880,246880,246 Frethog Frethog465,351 TaterfTaterf 5 1,237,155Taterf Taterf 797,935797,935 TaterfTaterf 451,561451,561 TaterfTaterf 497,582 497,582 Taterf Taterf 393,729393,729 Taterf Taterf447,849 FrethogFrethog 535,627535,627 AlureonAlureon 493,150 493,150 AlureonAlureon 436,566 436,566 RimecudRimecud 371,646 371,646 Alureon Alureon 308,673308,673 Alureon Alureon 441,722 RimecudRimecud 341,778341,778 FrethogFrethog 473,996473,996 BubnixBubnix 348,120 348,120 HamweqHamweq 289,603 289,603 Rimecud Rimecud289,629 289,629 Rimecud Rimecud318,041 AlureonAlureon 292,810 292,810 BubnixBubnix 471,243 471,243 RimecudRimecud 287,942287,942 ConfickerConficker 286,091286, 091 Hamwe Hamweqq 250,286250, 286 Conficker Conficker220,475220, 475 ConfickerConficker 237237,348, 348 RimecudRimecud 280280,440, 440 VobfusVobfus 251251,335, 335
    [Show full text]
  • Code Red Worm Propagation Modeling and Analysis ∗
    Code Red Worm Propagation Modeling and Analysis ∗ Cliff Changchun Zou Weibo Gong Don Towsley Dept. Electrical & Dept. Electrical & Dept. Computer Science Computer Engineering Computer Engineering Univ. Massachusetts Univ. Massachusetts Univ. Massachusetts Amherst, MA Amherst, MA Amherst, MA [email protected] [email protected] [email protected] ABSTRACT the Internet has become a powerful mechanism for propa- The Code Red worm incident of July 2001 has stimulated gating malicious software programs. Worms, defined as au- activities to model and analyze Internet worm propagation. tonomous programs that spread through computer networks In this paper we provide a careful analysis of Code Red prop- by searching, attacking, and infecting remote computers au- agation by accounting for two factors: one is the dynamic tomatically, have been developed for more than 10 years countermeasures taken by ISPs and users; the other is the since the first Morris worm [30]. Today, our computing in- slowed down worm infection rate because Code Red rampant frastructure is more vulnerable than ever before [28]. The propagation caused congestion and troubles to some routers. Code Red worm and Nimda worm incidents of 2001 have Based on the classical epidemic Kermack-Mckendrick model, shown us how vulnerable our networks are and how fast we derive a general Internet worm model called the two- a virulent worm can spread; furthermore, Weaver presented factor worm model. Simulations and numerical solutions some design principles for worms such that they could spread of the two-factor worm model match the observed data of even faster [34]. In order to defend against future worms, we Code Red worm better than previous models do.
    [Show full text]
  • Containing Conficker to Tame a Malware
    &#4#5###4#(#%#5#6#%#5#&###,#'#(#7#5#+#&#8##9##:65#,-;/< Know Your Enemy: Containing Conficker To Tame A Malware The Honeynet Project http://honeynet.org Felix Leder, Tillmann Werner Last Modified: 30th March 2009 (rev1) The Conficker worm has infected several million computers since it first started spreading in late 2008 but attempts to mitigate Conficker have not yet proved very successful. In this paper we present several potential methods to repel Conficker. The approaches presented take advantage of the way Conficker patches infected systems, which can be used to remotely detect a compromised system. Furthermore, we demonstrate various methods to detect and remove Conficker locally and a potential vaccination tool is presented. Finally, the domain name generation mechanism for all three Conficker variants is discussed in detail and an overview of the potential for upcoming domain collisions in version .C is provided. Tools for all the ideas presented here are freely available for download from [9], including source code. !"#$%&'()*+&$(% The big years of wide-area network spreading worms were 2003 and 2004, the years of Blaster [1] and Sasser [2]. About four years later, in late 2008, we witnessed a similar worm that exploits the MS08-067 server service vulnerability in Windows [3]: Conficker. Like its forerunners, Conficker exploits a stack corruption vulnerability to introduce and execute shellcode on affected Windows systems, download a copy of itself, infect the host and continue spreading. SRI has published an excellent and detailed analysis of the malware [4]. The scope of this paper is different: we propose ideas on how to identify, mitigate and remove Conficker bots.
    [Show full text]
  • Ethical Hacking
    Official Certified Ethical Hacker Review Guide Steven DeFino Intense School, Senior Security Instructor and Consultant Contributing Authors Barry Kaufman, Director of Intense School Nick Valenteen, Intense School, Senior Security Instructor Larry Greenblatt, Intense School, Senior Security Instructor Australia • Brazil • Japan • Korea • Mexico • Singapore • Spain • United Kingdom • United States Official Certified Ethical Hacker © 2010 Course Technology, Cengage Learning Review Guide ALL RIGHTS RESERVED. No part of this work covered by the copyright herein Steven DeFino may be reproduced, transmitted, stored or used in any form or by any means Barry Kaufman graphic, electronic, or mechanical, including but not limited to photocopying, Nick Valenteen recording, scanning, digitizing, taping, Web distribution, information networks, Larry Greenblatt or information storage and retrieval systems, except as permitted under Section 107 or 108 of the 1976 United States Copyright Act, without the prior Vice President, Career and written permission of the publisher. Professional Editorial: Dave Garza Executive Editor: Stephen Helba For product information and technology assistance, contact us at Managing Editor: Marah Bellegarde Cengage Learning Customer & Sales Support, 1-800-354-9706 For permission to use material from this text or product, Senior Product Manager: submit all requests online at www.cengage.com/permissions Michelle Ruelos Cannistraci Further permissions questions can be e-mailed to Editorial Assistant: Meghan Orvis [email protected]
    [Show full text]